Agentless SSH Key Investigation System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security systems require software agents on host computers for intrusion detection, which are resource-intensive, unreliable, and can alert intruders, while agentless solutions lack comprehensive threat detection capabilities and are resource-heavy or invasive.
Innovation Solution
An agentless investigation system that uses investigative modules to scan host computers for SSH public keys and other authentication tokens without installing software agents, minimizing resource usage and avoiding detection by intruders.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software agents are installed on host computers for security scanning, then threat detection capability is improved, but system resource consumption increases
Solution Approach 1:
The patent introduces a central management server as an intermediary that performs security scanning operations remotely. Instead of installing resource-intensive security agents on each host computer, the management server acts as a mediator that connects to hosts and performs scans without requiring local software installation. This resolves the contradiction by maintaining threat detection capability while eliminating the need for hosts to run resource-consuming security software.
Solution Approach 2:
The patent extracts the security scanning functionality from the host computers and centralizes it on a remote management server. By removing the security agent software from the hosts and consolidating scanning operations on a central server, the system maintains comprehensive threat detection while eliminating the CPU and RAM consumption that would occur on individual host systems.
2Reliability
If software agents are deployed across multiple host computers, then security coverage is improved, but deployment complexity and maintenance difficulty increase
Solution Approach 1:
The patent creates a universal security management system where a single management server provides security scanning services to multiple host computers. Instead of each host requiring its own dedicated security agent, the universal management server serves all hosts, simplifying deployment to just one system while maintaining comprehensive security coverage across the entire network.
Solution Approach 2:
The central management server serves as an intermediary that handles all security operations for multiple hosts. This single intermediary point of control eliminates the complexity of managing multiple distributed agents, as all security policies, scans, and updates are coordinated through the central server rather than requiring individual configuration on each host.
3Speed
If security scanning is performed continuously, then threat detection speed is improved, but host system performance degradation increases
Solution Approach 1:
The patent uses the central management server as an intermediary that performs scanning operations remotely without burdening the host system resources. The management server handles all the computational workload for security scans, allowing continuous or frequent scanning to occur without impacting the productivity or performance of the monitored host computers.
Solution Approach 2:
The patent moves the security scanning operation from the local dimension (host computer resources) to a remote dimension (management server resources). By performing scans from another dimensional location—the central server rather than local hosts—the system enables continuous threat detection while preserving host system performance, as the scanning workload exists in a separate computational dimension.
Data Source
AI summary
A system and method are provided for investigating a remote host computer by using an agentless investigation system that includes a computer system with a computer processor coupled to a system memory and programmed with computer readable instructions. The method includes establishing a connection with the host computer and sending at least one agentless investigative module to the host computer. The investigative module runs on the host computer to perform at least one investigative function on the host computer. The investigative function includes an investigation of the host computer to ascertain if there are any user accounts of the host computer that have data forms including at least one authentication token in the form of an SSH public key. The investigative module is configured to locate the SSH public key and collect investigation data corresponding to the SSH public key.


